Denver, CO

Salary
—
Posted
Jul 30, 2026
Location
Denver, CO
Last confirmed open
Sep 24, 2026

What this job asks for AI summary

This role sits within Bank of America's Global Information Security IAM team and is focused on administering and maintaining RACF security on z/OS mainframe environments. Day-to-day work includes managing security profiles, implementing access controls, troubleshooting incidents, supporting mainframe migrations and disaster recovery, and identifying automation opportunities. The position involves rotating 24/7 on-call support and regular interaction with audit, compliance, and senior stakeholders.

Mid level · 3+ years · Denver-Aurora-Lakewood, CO · Full-time

Must have (3)
RACF · 3+ yrsz/OSIAM · 3+ yrs
Nice to have (7)
zSecure or VanguardTSO/ISPFJCLCARLaREXXExcelServiceNow

“or” means any one of them counts — you don't need all of them.

Posted 2 times — it's one opening, so apply once.

We read this from the posting text with AI. Skim the description below before ruling yourself out.

How this req sits in the market our data

Roughly 3 people in the Denver-Aurora-Lakewood, CO area plausibly meet what this posting asks for (information security analysts). range 1–5

Applicant volume Moderate — A normal amount of company. The rare requirements below are what will separate a shortlisted application from the rest.

What gives you an edge
z/OS

Rare in this occupation — lead with these, and say what you built with them.

What won't set you apart
IAM45%

Most people in this occupation already list these. Still required — just not what gets you shortlisted.

What the occupation pays Median $139,675 (middle half $110,017–$174,679).

Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Aug 1, 2026. It is a model, not a headcount.

Why we read it this way (4)

The role is posted across four locations (Denver CO, Washington DC, Boston MA, Chicago IL); Denver is listed first and used as the primary metro here.

SOC classification is a genuine judgment call: the role's primary work is administering RACF security profiles and access controls on a mainframe (closer to 15-1244 systems administration), but it sits explicitly within an Information Security/IAM function and involves compliance, audit, and incident analysis (closer to 15-1212). 15-1212 was chosen because the IAM/security-policy framing dominates the responsibilities; 15-1244 is the runner-up.

The 'Experience with' block in Required Qualifications lists several technologies (zSecure/Vanguard, TSO/ISPF, JCL, CARLa, REXX, USS Security, AI for automation, Excel, ServiceNow) under a single bullet. These are treated as preferred rather than hard gates because the phrasing 'Experience with:' introduces a list of examples rather than individually gating requirements, and USS Security and AI for automation are too generic to emit as named skills.

No compensation figures are stated in the posting.

Read the full posting

The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.

Apply

Apply on employer site ↗